Malware

What is “ML/PE-A + Troj/Zbot-DUZ”?

Malware Removal

The ML/PE-A + Troj/Zbot-DUZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Zbot-DUZ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine ML/PE-A + Troj/Zbot-DUZ?


File Info:

name: 83BD2CCB9241A2D48DD7.mlw
path: /opt/CAPEv2/storage/binaries/173d23baffe97c1c2ceef924176d80fa1185a0d486cad669b9999fc1819e0f3b
crc32: C65C17BD
md5: 83bd2ccb9241a2d48dd7e2f5bfb0b892
sha1: ed36daede34b3a29009170d4a08d3cd65e7097af
sha256: 173d23baffe97c1c2ceef924176d80fa1185a0d486cad669b9999fc1819e0f3b
sha512: 95a4f18f4596430a0ed23c5f381f724e62e85ed5cdf97eb5ec8aeae02fd651d3dd7610eb7851ed7806eb4f499bb69881102886e2fcc4bb1963f8a8f5a1650fe1
ssdeep: 6144:GuNMh5V1pEbsXafiFUsb3gP4qfWjRh93SmpFv:U5VrCriuCu4gIRhMmrv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18264E04B795CC65DC76E88BF270A07ED09D0FBC2C359E1B7BD6BD54C4C242602A362A6
sha3_384: 9f842739854ae3972c9b6e712678d93868506b87baf11600a09a8336c6790b00553fef19d4c808ae7c6c10a7af43d645
ep_bytes: 558bec518bd58bc98bc08bc08bc98955
timestamp: 2013-02-22 15:41:10

Version Info:

0: [No Data]

ML/PE-A + Troj/Zbot-DUZ also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lIty
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.FakeAlert.DFJ
FireEyeGeneric.mg.83bd2ccb9241a2d4
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacTrojan.FakeAlert.DFJ
MalwarebytesMalware.AI.3331086531
ZillyaTrojan.Zbot.Win32.106772
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f26d1 )
AlibabaTrojanPSW:Win32/Karagany.4367ea2a
K7GWTrojan ( 0040f26d1 )
Cybereasonmalicious.b9241a
BitDefenderThetaGen:NN.ZexaF.34212.uqW@aq5cEddc
VirITTrojan.Win32.Generic.BXAC
CyrenW32/Tepfer.C.gen!Eldorado
SymantecTrojan.Zbot!gen39
ESET-NOD32Win32/Spy.Zbot.AAU
TrendMicro-HouseCallTSPY_ZBOT.SMODX
Paloaltogeneric.ml
ClamAVWin.Packed.Zbot-9754450-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.FakeAlert.DFJ
NANO-AntivirusTrojan.Win32.Zbot.boccmk
SUPERAntiSpywareTrojan.Agent/Gen-Simda
AvastWin32:Karagany
RisingTrojan.Agent!1.674E (CLOUD)
Ad-AwareTrojan.FakeAlert.DFJ
TACHYONTrojan-Spy/W32.ZBot.330240.Z
EmsisoftTrojan.FakeAlert.DFJ (B)
ComodoApplication.Win32.LoadMoney.ZED@6e0wcr
DrWebTrojan.PWS.Panda.3629
VIPRETrojan.Win32.Zbot.dhnb (v)
TrendMicroTSPY_ZBOT.SMODX
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
SentinelOneStatic AI – Malicious PE
SophosML/PE-A + Troj/Zbot-DUZ
APEXMalicious
JiangminTrojanSpy.Zbot.cvzb
WebrootW32.InfoStealer.Zeus
AviraTR/Spy.Zbot.1633288
Antiy-AVLTrojan/Generic.ASMalwS.138322
KingsoftWin32.Troj.Zbot.jg.(kcloud)
GridinsoftRansom.Win32.Zbot.sa
GDataTrojan.FakeAlert.DFJ
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R54901
Acronissuspicious
McAfeePWS-Zbot-FAKU!83BD2CCB9241
MAXmalware (ai score=100)
VBA32BScope.Malware-Cryptor.SB.01798
TencentMalware.Win32.Gencirc.10b87385
YandexTrojan.GenAsa!ldzaKTtWt+w
IkarusTrojan-PWS.Win32.Zbot
FortinetW32/Zbot.R!tr
AVGWin32:Karagany
PandaTrj/Hexas.HEU
CrowdStrikewin/malicious_confidence_90% (W)

How to remove ML/PE-A + Troj/Zbot-DUZ?

ML/PE-A + Troj/Zbot-DUZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment